Vulnerability Description
There is a Information Disclosure vulnerability in anjuta/plugins/document-manager/anjuta-bookmarks.c. This issue was caused by the incorrect use of libxml2 API. The vendor forgot to call 'g_free()' to release the return value of 'xmlGetProp()'.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnome | Anjuta | 2.0.0 |
Related Weaknesses (CWE)
References
- https://gitlab.gnome.org/GNOME/anjuta/-/issues/12Issue TrackingThird Party Advisory
- https://gitlab.gnome.org/GNOME/anjuta/-/issues/12Issue TrackingThird Party Advisory
FAQ
What is CVE-2021-42522?
CVE-2021-42522 is a vulnerability with a CVSS score of 7.5 (HIGH). There is a Information Disclosure vulnerability in anjuta/plugins/document-manager/anjuta-bookmarks.c. This issue was caused by the incorrect use of libxml2 API. The vendor forgot to call 'g_free()' t...
How severe is CVE-2021-42522?
CVE-2021-42522 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-42522?
Check the references section above for vendor advisories and patch information. Affected products include: Gnome Anjuta.